Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

229 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.64%—Stivasoft Phpjabbers Newsletter Script30/12/201717/6/2026
PHPJabbers PHP Newsletter Script 4.2 has stored XSS in lists in the admin panel.
ModificadaMedia (4)0.39%—Cisco Jabber30/11/201717/6/2026
A vulnerability in Cisco Jabber for Windows could allow an unauthenticated, local attacker to access sensitive communications made by the Jabber client. An attacker could exploit this vulnerability to gain information to conduct additional attacks. The vulnerability is due to the way Cisco Jabber for Windows handles…
ModificadaMedia (5.4)0.64%—Cisco Jabber30/11/201717/6/2026
A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and iOS could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of…
ModificadaMedia (6.1)1.2%—Cisco Jabber30/11/201717/6/2026
A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and iOS could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient…
ModificadaMedia (5.5)0.36%—Cisco JabberCisco Webex Meeting Center19/10/201717/6/2026
A vulnerability in the web interface of Cisco Jabber could allow an authenticated, local attacker to retrieve user profile information from the affected software, which could lead to the disclosure of confidential information. The vulnerability is due to a lack of input and validation checks in the affected software.…
ModificadaMedia (5.5)0.36%—Cisco Jabber19/10/201717/6/2026
A vulnerability in the web interface of Cisco Jabber for Windows Client could allow an authenticated, local attacker to retrieve user profile information, which could lead to the disclosure of confidential information. The vulnerability is due to a lack of input- and validation-checking mechanisms in the system. An…
ModificadaMedia (6.1)1.0%—Phpjabbers Rate ME16/10/201717/6/2026
rate-me.php in Rate Me 1.0 has XSS via the id field in a rate action.
ModificadaMedia (6.1)1.2%—Cisco Jabber Guest7/8/201717/6/2026
A vulnerability in the web-based management interface of Cisco Jabber Guest Server 10.6(9), 11.0(0), and 11.0(1) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software. The vulnerability is due to…
ModificadaCrítica (9.8)2.8%—Jabberd24/7/201717/6/2026
JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.
ModificadaMedia (6.5)1.4%—Cisco Jabber Guest26/12/201617/6/2026
A vulnerability in the Cisco Jabber Guest Server could allow an unauthenticated, remote attacker to initiate connections to arbitrary hosts. More Information: CSCvc31635. Known Affected Releases: 10.6(9). Known Fixed Releases: 11.0(0).
ModificadaAlta (7.5)8.3%—Cisco IOS XECisco Webex Meeting CenterCisco DX Series IP Phones FirmwareCisco IP Phone 7800 Series Firmware+1021/4/201617/6/2026
The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted fields in SRTP packets, aka Bug ID CSCux00686.
ModificadaMedia (6.1)1.0%—Cisco Jabber Guest6/2/201617/6/2026
Cross-site scripting (XSS) vulnerability in the management interface in Cisco Jabber Guest Server 10.6(8) allows remote attackers to inject arbitrary web script or HTML via the host tag parameter, aka Bug ID CSCuy08224.
ModificadaMedia (5.9)1.3%—Cisco Jabber26/12/201517/6/2026
Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STARTTLS downgrade attacks and trigger cleartext XMPP sessions via unspecified vectors, aka Bug ID CSCuw87419.
ModificadaMedia (6.5)1.9%—Jabberd212/8/201517/6/2026
c2s/c2s.c in Jabber Open Source Server 2.3.2 and earlier truncates data without ensuring it remains valid UTF-8, which allows remote authenticated users to read system memory or possibly have other unspecified impact via a crafted JID.
ModificadaMedia (5)2.6%—Cisco Jabber24/6/201517/6/2026
The web-based user interface in Cisco Jabber through 9.6(3) and 9.7 through 9.7(5) on Windows allows remote attackers to obtain sensitive information via a crafted value in a GET request, aka Bug IDs CSCuu65622 and CSCuu70858.
ModificadaAlta (7.5)1.2%💥 ExploitPhpjabbers Event Booking Calendar13/1/201517/6/2026
SQL injection vulnerability in load-calendar.php in PHPJabbers Event Booking Calendar 2.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter.
ModificadaMedia (6.8)2.0%💥 ExploitPhpjabbers Event Booking Calendar13/1/201517/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Event Booking Calendar 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) change the username and password of the administrator via an update action to the AdminOptions controller or conduct cross-site…
ModificadaMedia (5)7.7%💥 ExploitPhpjabbers Appointment Scheduler13/1/201517/6/2026
Directory traversal vulnerability in PHPJabbers Appointment Scheduler 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a pjActionDownload action to the pjBackup controller.
ModificadaMedia (6.8)2.3%💥 ExploitPhpjabbers Appointment Scheduler13/1/201517/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the i18n[1][name] parameter in a pjActionCreate action to the pjAdminServices…
ModificadaMedia (4.3)1.8%—Cisco Jabber Guest23/12/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Guest Server in Cisco Jabber allows remote attackers to inject arbitrary web script or HTML via a (1) GET or (2) POST parameter, aka Bug ID CSCus08074.
ModificadaMedia (4.3)1.8%—Cisco Jabber Guest23/12/201417/6/2026
The API in the Guest Server in Cisco Jabber, when HTML5 is used, allows remote attackers to obtain sensitive information by sniffing the network during an HTTP (1) GET or (2) POST response, aka Bug ID CSCus19801.
ModificadaMedia (4.3)1.8%—Cisco Jabber Guest23/12/201417/6/2026
The API in the Guest Server in Cisco Jabber, when the HTML5 CORS feature is used, allows remote attackers to obtain sensitive information by sniffing the network during an HTTP (1) GET or (2) POST request, aka Bug ID CSCus19789.
ModificadaMedia (5)1.3%—Process-one Ejabberd25/10/201417/6/2026
ejabberd before 2.1.13 does not enforce the starttls_required setting when compression is used, which causes clients to establish connections without encryption.
ModificadaMedia (4.3)5.5%—Cisco Jabber16/1/201417/6/2026
Directory traversal vulnerability in the Send Screen Capture implementation in Cisco Jabber 9.2(.1) and earlier on Windows allows remote attackers to upload arbitrary types of files, and consequently execute arbitrary code, via modified packets, aka Bug ID CSCug48056.
ModificadaMedia (4.3)1.6%—Process-one Ejabberd17/10/201317/6/2026
The TLS driver in ejabberd before 2.1.12 supports (1) SSLv2 and (2) weak SSL ciphers, which makes it easier for remote attackers to obtain sensitive information via a brute-force attack.
Orbitaley — Vulnerabilidades